When Colorado passed the Colorado AI Act (CAIA) in 2024, it became the first US state to adopt a comprehensive, risk-based approach to AI regulation.
The law attracted national attention because it introduced requirements around algorithmic discrimination, risk management programs, impact assessments, and consumer protections for high-risk AI systems. Organizations spent much of 2024 and 2025 evaluating how the framework would affect their AI governance programs.
Following stakeholder feedback, implementation delays, litigation, and recommendations from Colorado's AI Policy Working Group, lawmakers passed Senate Bill 26-189 in May 2026. The Governor signed the legislation on May 14, 2026, repealing and replacing the original Colorado AI Act.
The new law takes effect on January 1, 2027. For organizations that have been tracking Colorado's AI requirements, the conversation now shifts from the original AI Act to a narrower framework focused on automated decision-making technology (ADMT).
From AI Systems to Automated Decision-Making Technology
One of the most significant changes is the law's shift away from broad regulation of AI systems. The original Colorado AI Act focused on "high-risk AI systems" and sought to address algorithmic discrimination through governance, assessment, and oversight requirements.
The replacement law focuses instead on covered automated decision-making technology used to materially influence consequential decisions affecting consumers, including Colorado-based employees and job applicants.
A system used to evaluate job applicants, support lending decisions, determine housing eligibility, or influence access to healthcare services may fall within scope because it contributes to consequential decisions that affect individuals.
Other technologies are expressly excluded. The law carves out a range of lower-risk uses, including spam filtering, cybersecurity tools, fraud prevention controls, routine administrative functions, marketing and advertising activities, and tools that summarize information for human review without materially influencing outcomes.
For organizations, the first step toward compliance is understanding which technologies fall within these boundaries and which do not.
What Changed Under the New Framework
The new law removes several provisions that defined the original Colorado AI Act.
Most notably, lawmakers eliminated requirements tied to algorithmic discrimination governance. The revised framework also removes obligations related to risk management programs, annual impact assessments, and certain disclosures when consumers interact with non-obvious AI systems.
These changes significantly reduce the governance and documentation burden that many organizations had been preparing for under the 2024 law.
At the same time, the replacement legislation does not eliminate compliance obligations entirely. Instead, it concentrates requirements around transparency, documentation, and consumer rights.
The result is a framework that is narrower in scope while maintaining obligations for organizations that deploy decision-making technologies in consequential contexts.
What Requirements Remain for Developers and Deployers
Although the new law is less prescriptive than the original Colorado AI Act, organizations still need to prepare for several operational requirements before January 2027.
For developers, the focus centers on providing deployers with information necessary to understand and appropriately use covered technologies.
This includes documentation related to intended uses, categories of training data, known limitations, foreseeable risks, and other technical information that helps organizations evaluate how systems perform in practice.
For deployers, the emphasis shifts toward transparency and consumer rights. Organizations using covered automated decision-making technologies must provide notices before use, support disclosures following adverse outcomes, and establish mechanisms that allow consumers to exercise specific rights.
These rights include the ability to request information, correct data, and obtain meaningful human review in certain circumstances. The challenge becomes less about documenting risk management methodologies and more about operationalizing transparency and rights fulfillment across business processes.
Transparency and Consumer Rights Remain Central
While Colorado's new law departs from the original risk-based framework, it preserves a regulatory focus that is becoming increasingly common across the United States.
States continue to place growing emphasis on how organizations explain automated decisions and how consumers exercise rights when those decisions affect them.
Connecticut's amended privacy law introduces expanded rights around profiling and automated decision-making, while California continues to advance discussions around automated decision-making technology. Other states are incorporating transparency obligations, consumer review rights, and assessment requirements into broader privacy frameworks.
The result is a regulatory environment where organizations increasingly need visibility into how automated systems influence consequential outcomes. Whether a law uses the language of AI systems, profiling, or automated decision-making technology, the operational questions remain similar:
- What decisions are being made?
- What data supports those decisions?
- How are outcomes communicated?
- What options exist when individuals want to challenge or review those outcomes?
Preparing for January 2027
Organizations evaluating readiness for Colorado's new law should focus on a few foundational areas.
First, identify where automated decision-making technology is used across the organization, particularly in areas such as employment, financial services, housing, education, healthcare, and other consequential decision contexts.
Second, review notice and disclosure processes. Organizations should understand when notifications may be required, what information must be provided, and how communications are delivered consistently.
Third, evaluate consumer rights workflows. Requests for information, correction, or human review require operational processes that connect governance requirements to day-to-day activities.
Finally, review documentation practices across both development and deployment functions. Developers and deployers should understand what information must be maintained, shared, and updated to support compliance.
Colorado's New Direction for AI Governance
Colorado's 2026 legislation represents one of the most significant shifts in US AI regulation to date. Rather than implementing the broad framework introduced in 2024, lawmakers adopted a more targeted approach centered on automated decision-making technology, transparency, and consumer rights.
For organizations, the change may reduce some governance obligations while maintaining meaningful requirements around documentation, notices, disclosures, and review mechanisms.
As state AI regulation continues to evolve, the ability to connect governance, compliance, and operational execution remains essential.
For deeper analysis of Colorado's evolving AI framework and global regulatory developments, explore OneTrust DataGuidance.
To operationalize AI governance requirements across policies, assessments, inventories, and compliance workflows, learn how OneTrust AI Governance helps organizations govern AI systems at scale.
Key Questions About Colorado's New ADMT Law